Fedora Account System
Red Hat Associate
Red Hat Customer
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:22120 https://access.redhat.com/errata/RHSA-2026:22120
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:22121 https://access.redhat.com/errata/RHSA-2026:22121
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:22112 https://access.redhat.com/errata/RHSA-2026:22112
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:49702 https://access.redhat.com/errata/RHSA-2026:49702
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:49712 https://access.redhat.com/errata/RHSA-2026:49712